Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Death to Passwords! They Don’t Work, So What’s Next?
Articles

Death to Passwords! They Don’t Work, So What’s Next?

ISBuzz TeamBy ISBuzz TeamSeptember 2, 2014Updated:September 4, 20145 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

We’ve all seen the Hollywood movies. Retinal eye scanners that open secret passageways. Facial recognition systems and handprint scanners that verify the good guys are who they say they are.

FREE Ebook: A New Approach To Managing Employees’ Personal Internet Use At Work

In truth, corporate security in the real world is much more mundane. The most common model requires employees to enter a six or eight character password to access a secure environment. For many years, the model was good enough, even though many man hours were spent resetting or unlocking accounts when the password just couldn’t be remembered.

Today, the model is broken because passwords, as they exist, have outlived their usefulness. In the old model, the workplace was always on-premise, and people spent most of their time in their physical place of employment. But in today’s society, workers are just as apt to be in their own living room, in a client’s conference room, or in an overseas hotel room.

A simple password just doesn’t cut it anymore. It’s not personal enough. It’s not secure enough. Unfortunately, increasing the complexity of a password isn’t the solution because it would just mean more time wasted in lockouts and resets. What’s more, today’s workforce doesn’t just utilize enterprise technology that is configured for on-premise usage. The mobile workforce of today utilizes social media technology and flexible remote tools and applications. Work happens anytime, anywhere.

Empowering the innovative workforce of today means replacing the restrictive passwords of old with something much more intuitive, like passphrases. Enabling passphrases will ultimately empower the innovative workforce with better security. Employees will feel they have more ownership over their own identities and, as IT professionals, we should encourage better security measures that increase productivity.
[wp_ad_camp_4]
After all, identity has become just as important as the data it authorizes. Moving from an eight character encrypted password to a 26 character password only introduces complexity. Educating the workforce on the eradication of the password and the implementation of the passphrase will empower people to lock down a single identity access once and for all.

Today, only about two percent of enterprises have implemented passphrases. Why? Because most CIOs fear the repercussions of making access more complex, such as massive lockouts for end users and skyrocketing helpdesk calls.

Employees unable to do their job because they no longer have access to the tools they need is the ultimate technology nightmare. But this fear simply enables the bad guys to develop more complex hacking algorithms against the eight character password.

Let’s take a closer look at what passphrases really are. Yes, they are inherently more complex than passwords, but they are also inherently more intuitive, and that is what eliminates the complexity.

In fact, passphrases are nothing new. We’ve all used them at one time or another to help us memorize complex things. To learn the order of planets from the sun, for instance, school kids commonly employ the phrase: My Very Educated Mother Just Served Us Nachos. That’s the easiest and most intuitive way to memorize Mercury, Venus, Earth, Mars, Jupiter, Saturn, Uranus, Neptune.

With a little guidance from the IT staff, passphrases can be a very effective security measure to help isolate and protect corporate data. Here are some passphrase guidelines intended to get everyone away from using passwords and in the habit of using passphrases, which results in stronger and more intuitive security.

Passphrase Guideline #1

Total number of letters in my name; high school mascot; power department; favorite car:

Passphrase: 14_Panther_CPS_Corvette

Passphrase Guideline #2

Four wheel drive or two wheel drive, margarita on the rocks or chilled, favorite fruit, area code of your favorite destination:

Passphrase: 4x4_Chilled_Mango_808

Passphrase Guideline #3

Local grocery store; color of your trash cans; favorite cheese, mother’s zip code:

Passphrase: HEB_Green_MontereyJack_96808

As you can see from the examples, even if everyone is following the same guidelines, you will still get wildly divergent passphrases. Example #3, for instance, produced a whopping 27 character passphrase. The passphrase itself is easy to remember, even though a 27 character password would be very difficult. Once the workforce gets the hang of it, they can mix and match several guidelines for even more random passphrases in the future.

It’s time to kill the password and replace it with the passphrase. The IT staff can play a crucial role in transitioning today’s workers away from old-school passwords to modern day passphrases.

About Centrify


Centrify Logo-HiRes
Centrify provides unified identity management across data center, cloud and mobile environments that deliver a single sign-on (SSO) for users and a simplified identity infrastructure for IT. Centrify’s unified identity management software and cloud-based Identity-as-a-Service (IDaaS) solutions leverage an organization’s existing identity infrastructure to enable single sign-on, multi-factor authentication, privileged identity management, auditing for compliance and mobile device management. Centrify customers can typically reduce their total cost of identity management and compliance by more than 50 percent, while improving business agility and overall security.  Centrify is used by more than 5,000 customers worldwide, including nearly half of the Fortune 50 and more than 60 Federal agencies.

For more information, please visit http://www.centrify.com/

 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}